Staff Cybersecurity Architect – Data Security, Data Loss Prevention
Posted 2026-05-06
Remote, USA
Full-time
Immediate Start
- Job Description:
- Develop, maintain, and evolve enterprise data security and data loss prevention architectures aligned to business objectives, regulatory requirements, and data classification standards.
- Design and operationalize Microsoft Purview Information Protection and DLP capabilities, including sensitivity labeling, classification, policy enforcement, and user experience considerations.
- Architect and implement Microsoft Defender capabilities (Endpoint, Identity, Office 365, Cloud Apps) to protect data throughout its lifecycle.
- Author and maintain data security and DLP standards, reference architectures, and technical guardrails aligned to NIST and internal security frameworks.
- Evaluate new platforms, tools, and vendors for strategic fit, security posture, and architectural impact.
- Requirements:
- Bachelor’s degree in arts/sciences (BA/BS) or equivalent experience – Required
- Active CIPT, CDPSE, CISSP certification – Preferred
- 8+ years of progressive experience in information technology security/infrastructure engineering/architecture – Required
- 6+ years of data security and data loss prevention control implementation/architecture experience focused on technical control design, implementation, and validation in enterprise environments - Required
- Deep understanding of industry best practices, ISO 27001/27701, SOC 2 and NIST aligned compliance and security frameworks, particularly as they relate to data protection and DLP – Required
- Strong technical background in data classification, Varonis Data Security, Microsoft Purview, and Microsoft Defender security suite across hybrid on-premise and multi-cloud infrastructure. – Required
- Proven experience supporting audit, regulatory, or certification efforts through technical control implementation and validation – Required
- Advanced analytical and problem solving skills with strong attention to detail – Required
- Strong understanding of cryptographic controls, certificate-based authentication, mutual TLS, and their role in zero trust and data protection architectures – Preferred
- Benefits:
- health, retirement, and other employee benefits
- annual bonus plan